CVE-2012-2378

Aliases:GHSA-vjpc-vf4f-82qg
Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 05 Jan 2013, 00:00
Last modified:06 Aug 2024, 19:34

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
4.24% LOW
4% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Jan 2013, 00:00
Published
Vulnerability first disclosed
06 Aug 2024, 19:34
Last Modified
Vulnerability information updated

Description

Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 4.24% Percentile: 89%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • apachecxf

    2.4.5 | 2.4.6 | 2.4.7 | 2.5.1 | 2.5.2 | 2.5.3 | 2.6.0

  • org.apache.cxfcxf

    ≥ 2.4.5, < 2.4.8 | ≥ 2.5.1, < 2.5.3 | ≥ 2.6.0, < 2.6.1

References (21)